ClickAider

Rootkit

Like Rich Tong, my fully patched home Windows box seems to have beem infected by a particularly nasty rootkit that is invisible to standard anti-spyware and anti-virus software; the main symptoms are randomly named six letter EXEs that generate browser popups.  RootkitRevealer from Sysinternals shows evidence of the rootkit but doesn’t identify it precisely and can’t clean it up on its own.  (Will System Restore help me here? )

The most dismaying thing is that some of the popups generated are for an anti-virus product call WinAntiVirusPRO, which is perhaps knowingly profiting off of the infect machines. I hope everyone avoids that software.

2 Comments so far
Leave a comment

[…] Rootkit - ugh. […]

[…] I finally scraped the evil rootkit out of my Windows box, ironically by way of Ubuntu. […]


Leave a comment

(required)

(required)